CVE-2019-2249
—CVSS 3.1
9.8 critical
EPSS
1%p71
Published
()
Modified
Description
Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9205, MDM9650, QCA8081, QCS605, SD 427, SD 435, SD 450, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX20, Snapdragon_High_Med_2016, SXR1130
- Vendors
- qualcomm
- Products
- ipq8074 firmware, mdm9205 firmware, mdm9650 firmware, qca8081 firmware, qcs605 firmware, sd 427 firmware, sd 435 firmware, sd 450 firmware, sd 625 firmware, sd 636 firmware, sd 665 firmware, sd 675 firmware
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.